{"id":1007,"date":"2014-01-05T15:34:40","date_gmt":"2014-01-05T19:34:40","guid":{"rendered":"http:\/\/blog.bitsofgenius.com\/?p=1007"},"modified":"2014-01-05T15:34:40","modified_gmt":"2014-01-05T19:34:40","slug":"user-beware-the-hidden-gotchas-of-the-verizon-fios-service","status":"publish","type":"post","link":"https:\/\/blog.bitsofgenius.com\/?p=1007","title":{"rendered":"User beware: the hidden gotchas of the Verizon FIOS service"},"content":{"rendered":"<p>Verizon FIOS is a fiber-optic system capable of delivering very fast internet feeds to residential consumers, in addition to its TV service. With upload speeds in excess of 25Mb, and download speeds in excess of 50Mb (its currently capable of 150Mb), you would think that this service beats cable internet and DSL internet hands down.<\/p>\n<p>Well, speed-wise it does. \u00a0But there are quite a few gotchas, including some not so apparent security risks. If you are not a casual residential user of the service and take the time to login to the router , you&#8217;ll quickly discover the Actiontec router provided by Verizon is a flashy, poorly designed child&#8217;s toy. \u00a0While the hardware is solid, the choice of firmware is dismal and, in my opinion, more than a bit dangerous. \u00a0It looks and behaves like someone&#8217;s abandoned science project, which was picked up and finished by the marketing department at Verizon. \u00a0There is no common sense whatsoever in its design or user-experience.<\/p>\n<p>And worse, the firmware\u00a0also initiates strange connections to Verizon servers, which make me question the router&#8217;s security and integrity. \u00a0Since I am engineer, I find it appalling what Verizon gives out as a core piece of the network in a user&#8217;s home&#8211;especially in light of the recently-revealed NSA eavesdropping and network penetration efforts and, before that, the years of black-ops efforts on the net to seize control of networks for bot armies, industrial espionage, monetary theft, etc, etc.<\/p>\n<p><span style=\"font-size: 13px;\">The real test of a good internet connection is not only the speed and how much your network can do for you, but more importantly how much people outside of your home network don&#8217;t have a chance to compromise it and, even worse, take control of it. Verizon FiOS architecture fails, quite frankly, very miserably on both of these accounts. Here&#8217;s a specific set of reasons why, broken down by the level of importance.<\/span><\/p>\n<p><em>Security and Network Ownership\/Management<\/em><\/p>\n<p>The Actiontec router has two network interfaces for the WAN (Internet-facing) connection. One is coax, and one is ethernet. \u00a0The box is setup by the installer with the coax connection, because the box is designed to work with the DVR unit to access the network for TV program information, etc. And, surprise surprise, the DVR only has a coax connection to access the internet.<\/p>\n<p>This is a very subtle, and very dirty trick to dissuade users from disconnecting the Actiontec router and putting in their own router. Publicly-available routers are known to use standard Cat 5 network connections, so a standard router won&#8217;t directly support a connection to the DVR. So this quagmire of giving up your onscreen programming guide to use your own router is created. \u00a0Most average users will give-in to using Verizon&#8217;s router because they don&#8217;t want to give up the programming guide on the TV, and don&#8217;t have the knowledge of how to work around that with their own router.<\/p>\n<p>Verizon, for any number of reasons, would love to control the traffic on their network&#8211;even to the extent of managing their company assigned router inside your house to enforce their corporate policy and thinking. \u00a0This is a very dangerous way of looking at the internet, which is designed for a free-flow of information. \u00a0I have documented a legal move made by Verizon in the past in this related post <a href=\"http:\/\/blog.bitsofgenius.com\/?p=529\" target=\"_blank\">here<\/a>, written a few months back, which\u00a0demonstrates why this is their motive.<\/p>\n<p>In addition to the business trick of discouraging alternate router usage, there are also some additional, open ports on the Actiontec router which indicate that it is\/can be centrally managed. \u00a0Centrally managed means the router can be exposing its settings. logs or even receive remote firmware upgrades at the will of Verizon. \u00a0This would violate the cardinal rule I have for any piece of electronic equipment which I own: updates allowed only when I am notified and approve.<\/p>\n<p>While some people will argue that this means a security hole can be patched quickly across the network, the converse is also true. \u00a0Because a large set of routers are available to a central management system, an intruder with ill-intent could potentially put a compromised firmware into that system for distribution. \u00a0Less aggressively, a release of firmware which has an undiscovered problem could potentially take thousands, if not millions of households offline at one time.<\/p>\n<p>And worse, because Verizon is a publicly traded company, the problem could be concealed, or described in a more generic form as a &#8220;network issue we are working to resolve&#8221; to mask the real cause of the problem in an attempt to protect stock values. \u00a0In the open source world, which DD-WRT is a part of, many people contribute, test, openly write about and scrutinize the software. \u00a0Because of the openness, the user has enough information to decide if an upgrade to their router is appropriate. \u00a0And if they decide an upgrade is appropriate, they decide upon the time.<\/p>\n<p>Even if DD-WRT were compromised, the chances of it being discovered and exposed are far greater due to its very open, public nature. \u00a0Not so with Verizon&#8217;s approach.<\/p>\n<p><em>The Awful User Experience of the Actiontec Router&#8217;s web management interface.<\/em><\/p>\n<p>In some ways, there are too many pain points in this browser interface to list. \u00a0But I will list the ones that stand out to me.<\/p>\n<ul>\n<li><em>Trying to get the user lost the moment they attempt to login.<\/em> \u00a0The very first one starts with the login screen for the router management. \u00a0As keystrokes are entered into the password text box of the dialog, the router will actually change the number of asterisks that appear to a larger or smaller number than actually typed. \u00a0This is so dumb. \u00a0Not only does it confuse the person who might be looking over the operator&#8217;s shoulder (the intent), but it royally confuses the operator as well. \u00a0When the feedback of what is being typed is not displayed, the only measure of accuracy the person typing has is cadence&#8211;a count that can match where the operator expects to be in the sequence. \u00a0And Verizon&#8217;s interface even screws that up. \u00a0I can not emphasize how asinine this is. \u00a0Most modern username\/password dialogs today have an option to unmask (i.e. don&#8217;t hide) the password. \u00a0After all, if you&#8217;re the only one in the room, what&#8217;s there to protect?<\/li>\n<li><em>\u00a0Locking yourself out of your own router.<\/em> \u00a0Want to have fun? \u00a0Enter a bad password in the password text box, and click the login button several times. \u00a0The box will actually lock you out, of your own network in your own house. \u00a0Every other router on the market will give you infinite chances to login to the router, if you are connecting from something that originates in the house (Wireless or LAN connections). \u00a0It is only the WAN origination points (somewhere from the outside to the network in the house) where a certain amount of consecutive failures will cause a lockout to occur. I was just stunned when I saw this. \u00a0Make me get up and recycle the power on my own router to try again, because you (Verizon) threw off my cadence when entering the password&#8211;come on !<\/li>\n<li><em>Extraordinarily\u00a0poor navigation.<\/em>\u00a0 The items are all over the place, poorly grouped, inconsistent, and diving down to a menu item often requires you to go back to the top and navigate all the way back down again for another action in that same area.<\/li>\n<li><em>No attempt to memorize any recurring answer the user gave.<\/em> \u00a0Certain areas are labeled as for advanced users only, requiring a click-through to approve going into them. \u00a0But each successive time you go into another &#8220;advanced users&#8221; area, you get asked again. \u00a0Add this in to the continuous deep-dives needed in the entire menu system, and the amount of time wasted for simple activity is astonishing.<\/li>\n<li><em>Advertising right on the home page.<\/em> \u00a0This is the most laughable to me. \u00a0Once you login, and every time you cycle back to the home page (which it does force you to do a lot), Verizon&#8217;s router displays advertising links on the right panel&#8211;of an equipment configuration page on the local router! \u00a0For those of you who wrote this site and let Verizon make this a requirement of you, super glue a brown paper bag of shame over your head.<\/li>\n<li><em>A mysterious port which you can not disable.<\/em> \u00a0\u00a0The router has NAT, but has a port authoriztion (TCP 4567) that is untouchable by the user. \u00a0This should be an automatic red flag that something is going on with an outside server, which Verizon will not allow you to turn off. \u00a0The port is known to be a point-of-access for Verizon to enter the router for their purposes. \u00a0They will call it customer support, but both the Actiontec and Westell boxes have been attacked and compromised on these ports.\u00a0<a style=\"line-height: 1.5em;\" href=\"http:\/\/forums.verizon.com\/t5\/FiOS-Internet\/Guy-accessed-remote-administration-port-4567-on-my-router-Thanks\/td-p\/241017\">http:\/\/forums.verizon.com\/t5\/FiOS-Internet\/Guy-accessed-remote-administration-port-4567-on-my-router-Thanks\/td-p\/241017<\/a><\/li>\n<\/ul>\n<p>Despite all of this, I still have Verizon FIOS as my ISP provider. \u00a0As long as my router is the main entry point to the home network, I can manage and protect it as I need. \u00a0I do find the path that Verizon has taken with this architecture very concerning. \u00a0It would also not be completely fair to say that Verizon is definitely the only one doing this, but be aware of the implications of using the company provided equipment for your home network.<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Verizon FIOS is a fiber-optic system capable of delivering very fast internet feeds to residential consumers, in addition to its TV service. With upload speeds in excess of 25Mb, and download speeds in excess of 50Mb (its currently capable of 150Mb), you would think that this service beats cable internet and DSL internet hands down. [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[21,20,13],"tags":[],"class_list":["post-1007","post","type-post","status-publish","format-standard","hentry","category-politics-and-public-policy","category-technologynetworking","category-technologythoughts"],"_links":{"self":[{"href":"https:\/\/blog.bitsofgenius.com\/index.php?rest_route=\/wp\/v2\/posts\/1007","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.bitsofgenius.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.bitsofgenius.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.bitsofgenius.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.bitsofgenius.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1007"}],"version-history":[{"count":26,"href":"https:\/\/blog.bitsofgenius.com\/index.php?rest_route=\/wp\/v2\/posts\/1007\/revisions"}],"predecessor-version":[{"id":1110,"href":"https:\/\/blog.bitsofgenius.com\/index.php?rest_route=\/wp\/v2\/posts\/1007\/revisions\/1110"}],"wp:attachment":[{"href":"https:\/\/blog.bitsofgenius.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1007"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.bitsofgenius.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1007"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.bitsofgenius.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1007"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}